Skip to content

LangChain and LangGraph

pip install "agentguard-oss[langchain]" langgraph

guarded_tool registers a function with the Guard and returns a LangChain StructuredTool. It works anywhere LangChain tools do, including LangGraph's ToolNode and prebuilt agents.

from agentguard import Guard
from agentguard.adapters.langchain import guarded_tool

guard = Guard("policy.yaml", audit="agentguard.jsonl")


def read_file(path: str) -> str:
    """Read a UTF-8 text file from the workspace."""
    with open(path, encoding="utf-8") as f:
        return f.read()


read_tool = guarded_tool(guard, read_file, capability="filesystem.read")

With LangGraph:

from langgraph.prebuilt import ToolNode

tools = ToolNode([read_tool])        # or create_react_agent(model, [read_tool])

Options

Argument Default Meaning
capability required The tool's capability
name, description function name, docstring What the model sees
return_denials True Return denials to the model as {"error": ..., "reasons": [...]}; False raises GuardDenied
**options Passed to guard.tool: executor, verifier, path_arg, ...

Already decorated with @guard.tool? Use from_guarded(guarded_function).

Async functions become async tools (ainvoke). A halted session or failed execution still raises, so LangChain reports a tool failure.

Warning

Give the agent only the returned tool. If the raw function is also available, the agent can call it without AgentGuard.